First published: Mon Jul 31 2023(Updated: )
An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The vulnerability allows an attacker to inject a malicious payload in the "Search for Package" field, which gets reflected back in the application's response, leading to the execution of arbitrary JavaScript code within the context of the victim's browser.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Webmin | =2.021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38309 is a Reflected Cross-Site Scripting (XSS) vulnerability discovered in Webmin 2.021.
CVE-2023-38309 allows an attacker to inject a malicious payload in the 'Search for Package' field in Webmin, resulting in a Reflected XSS attack.
The severity of CVE-2023-38309 is medium with a CVSS score of 6.1.
Webmin version 2.021 is affected by CVE-2023-38309.
To fix CVE-2023-38309, upgrade to a version of Webmin that is not affected by the vulnerability.